GPO and OU enumeration

Group Policy objects (GPOs) push configuration (and, usefully for an attacker, scheduled tasks, scripts, and group membership) to the users and computers they are linked to. A principal who can edit a GPO can run code on everything that GPO applies to. Enumeration here answers three questions: what GPOs exist, what they are linked to (so you know the blast radius), and who can modify them.

Mapping GPOs to their targets#

GPOs are linked to sites, domains, and organizational units via the gPLink attribute on the container. To know who a GPO affects, map GPO to link to the objects under that container:

code
# PowerView
Get-DomainGPO -Properties displayname,gpcfilesyspath
Get-DomainOU -Properties name,gplink
Get-DomainGPO -Identity '{GUID}' | Get-DomainOU   # resolve a GPO to its linked OUs
Get-DomainComputer -SearchBase 'OU=Workstations,DC=example,DC=local'   # who is under that OU
bash
# From Linux
nxc ldap <dc> -u user -p pass --gpo
ldapsearch ... '(objectClass=groupPolicyContainer)' displayName gPCFileSysPath

The gPCFileSysPath points at the GPO's files in SYSVOL (\\domain\SYSVOL\domain\Policies\{GUID}), readable by any domain user, which is where Group Policy Preferences passwords historically leaked.

Finding editable GPOs#

The escalation path is a GPO whose DACL grants a principal you control write access (WriteProperty/GenericWrite/GenericAll). Enumerate GPO permissions the same way as any object ACL:

code
Get-DomainGPO | Get-DomainObjectAcl -ResolveGUIDs |
  ? { $_.ActiveDirectoryRights -match 'WriteProperty|GenericWrite|GenericAll' }

BloodHound draws this as a GenericWrite/GPOAbuse edge from the principal to the GPO, and then shows every computer and user the GPO reaches.

Exploitation notes#

  • Prioritize GPOs linked to OUs that contain privileged or many computers; editing a GPO linked to a Domain Controllers OU is domain-critical.
  • A readable SYSVOL policy tree is worth grepping for cpassword (Group Policy Preferences) and for scripts referencing credentials.
  • Enumeration identifies the editable, high-reach GPO; the actual abuse (immediate scheduled task, script, or group membership push) is covered in the Group Policy section.

Tools#

  • PowerView Get-DomainGPO / Get-DomainOU: GPO and OU mapping with ACLs.
  • NetExec (nxc) ldap --gpo: GPO listing from Linux.
  • BloodHound: GPO-to-target reach and editable-GPO edges.

References#

  • The Hacker Recipes: Group policies
  • Microsoft: Group Policy architecture and gPLink

Cookie Consent

We use cookies to enhance your experience. Learn more